Skip to content

Rust SDK for Canton Network #407 - Milestone 3: Token Standard (CIP-56 V1 + CIP-0112 V2), External Signing, PQS Client, Conformance & Security Review

OPENIssue
by pedrodneves15-07-2026
150K CC requested
References:CIP-0056CIP-0112

Milestone 3: Token Standard (CIP-56 V1 + CIP-0112 V2), External Signing, PQS Client, Conformance & Security Review

  • Estimated delivery: Month 4.5 · Hard deadline: 6 months from grant approval.
  • Estimated effort: ~70 person-days plus the external audit window (V2 support — the Account model, allocation/executor settlement, and V2 transfer-event parsing — is absorbed here, since it lands largely through the M2 codegen; the total request is unchanged).
  • Deliverables:

- canton-token covering CIP-56 V1 and CIP-0112 V2: holdings, transfer instruction, allocations, choice-context, disclosed-contract / createdEventBlob handling, plus the V2 Account model, allocation/executor settlement, and V2 transfer-event parsing. - Interactive Submission with a pluggable signer (HSM/KMS-compatible). - canton-pqs typed PQS client (typed predicates compiled to parameterized JSONB queries, no hand-written SQL). - End-to-end token-standard transfer examples for both V1 (CIP-56) and V2 (CIP-0112 — an Account-based transfer/allocation); remaining canton-splice-* crates. - Conformance/integration test suite mapped to the Ledger Client Standard (each v1 capability has a corresponding conformance check) plus a published compatibility matrix (Rust toolchain versions × supported Canton / Daml-LF ranges × supported target platforms, and the token-standard versions V1/V2 each crate targets), exercised in CI (codegen output compiles and round-trips against real DARs; submit → observe → query verified on both gRPC and JSON transports). - Independent security review of the client, codegen, and token crates; the auditor and audit scope are agreed with the Tech & Ops security subcommittee and the scope document published before the review begins.

  • Verification: a V1 (CIP-56) transfer settles end to end on DevNet, and a V2 (CIP-0112) Account-based transfer/allocation is exercised against the V2 reference token (and Canton Coin's V2 path as it lands on DevNet); conformance suite green on the supported matrix; security-review critical/high findings remediated and a remediation summary published.

| Milestone | Payment | % of total | |---|---|---| | M3 — Token standard (V1 + V2), external signing, PQS client, conformance | 150,000 CC upon committee acceptance | ~11.5% |

_Originally posted by @pedrodneves in https://github.com/canton-foundation/canton-dev-fund/issues/407#issuecomment-4979838690_